Legal
Data Processing Addendum
Effective 25 September 2026 · Last updated 25 September 2026
Scrape Supply is a service operated by chiba enterprise LLC.
1. What this addendum is
This Data Processing Addendum is between you, the customer, and chiba enterprise LLC, a New Mexico limited liability company, with its office at 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States (“we”, “us”).
Where you are subject to the EU or UK GDPR, this addendum forms part of our Terms of Service and applies to lead data we process on your instructions. It does not cover your own account data — your email, organisation and billing records — which we handle as controller under the Privacy Policy. If this addendum and the Terms of Service conflict about lead data, this addendum wins.
2. The processing
- Subject matter: retrieving publicly listed business information for the search terms and locations you choose, verifying the phone numbers in it, and storing and delivering the results to you.
- Duration: for as long as you use the service, and until the data is deleted under section 8.
- Nature and purpose: collection, verification, storage, display and export of lead data, so that you can research and contact businesses.
- Categories of data: business listing data — business name, phone number, street address, website, rating, review count, coordinates and the raw listing record — and the phone-verification result (whether a number is valid, and its line type).
- Data subjects:businesses listed on public directories, which can include sole traders and businesses listed under a named individual, and so can include a person’s own phone number.
3. Your role and ours
You are the controller of lead data, and we are your processor. Your instructions are your use of the service — the searches you run, the results you keep, export or delete — together with these terms. We process lead data only on those instructions, unless the law requires otherwise, in which case we will tell you first unless the law forbids that. If we believe an instruction breaks data-protection law, we will tell you.
You are responsible for having a lawful basis for lead data and for giving any notices the law requires to the people it describes, including any notice owed under Article 14 of the GDPR for data obtained from a source other than the person.
4. Confidentiality
Anyone we authorise to process lead data is bound by a duty of confidentiality, whether by contract or by law.
5. Security
The measures we actually operate are:
- Encryption in transit: all traffic to the service, and between our systems and our providers over the internet, uses TLS (HTTPS).
- Tenant isolation in the database: every record belongs to exactly one organisation, and row-level security in the database refuses reads across organisations even if the application asked for them.
- Access control: every page and request is checked against the signed-in user and their organisation; customers have read-only access to their own records, and writes go through a small set of controlled database functions.
- Protected credentials:passwords are stored only as one-way hashes by Supabase Auth; administrative keys are held on the server side only — in our hosting providers’ encrypted environment settings, or on the server we operate with access restricted to its administrator — are kept out of source code, and are never sent to the browser.
We hold no third-party security certification and do not claim one.
6. Sub-processors
You authorise us to use the following sub-processors. Each is bound by written data-protection terms, and we remain responsible to you for their processing:
- Supabase — Database, authentication and file storage
- Vercel — Hosting for the web application
- Stripe — Payment processing and hosted checkout
- Resend — Transactional email delivery
- ClearoutPhone — Phone number verification
- Hetzner — Hosts the dedicated server we operate, which runs the scraping engine (Germany)
We will give you at least 30 days’ notice by email before adding or replacing a sub-processor, and you may object. If you object on reasonable data-protection grounds and we cannot resolve it, you may close your account before the change takes effect, and we will refund your unused credits as for a closure that is not your breach under the Refund Policy.
7. Helping you meet your obligations
- Requests from individuals: if someone asks us directly to access, correct or delete their data, we will pass the request to you where we can identify you as the customer concerned, and we will help you respond to requests you receive, taking into account what the service can do.
- Personal data breaches: we will notify you without undue delay after becoming aware of a breach affecting lead data we process for you, with the information we have and as it becomes available.
- Assessments: we will give you reasonable information for any data-protection impact assessment or consultation with a supervisory authority that concerns our processing.
8. Deletion at the end of the service
When your account closes, however it closes, we delete lead data we hold for you within 30 days, unless the law requires us to keep it. You can export your results as CSV at any time before then. We keep the record of any removal or objection request, so that the business or person stays excluded from future results.
9. Information and audits
On request, we will make available the information reasonably necessary to show that we meet our obligations under this addendum, and answer reasonable written questions about our processing. That information is how audits under this addendum are carried out.
10. International transfers
Our infrastructure spans the United States and Germany. Where lead data moves out of the European Economic Area, the European Commission’s Standard Contractual Clauses apply to the transfer; where it moves out of the United Kingdom, the UK International Data Transfer Agreement or the UK Addendum to those clauses applies.
11. Contact
chiba enterprise LLC, 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States. Email admin@systemease.net, which is also the data protection contact.